PT-2007-4228 · Isc+2 · Isc Bind+2

Amit Klein

·

Publicado

2007-09-11

·

Atualizado

2018-10-16

·

CVE-2007-2930

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ISC BIND 8 versions prior to 8.4.7-P1
Description The issue affects the NSID SHUFFLE ONLY and NSID USE POOL PRNG algorithms, which generate predictable DNS query identifiers when sending outgoing queries, such as NOTIFY messages, when answering questions as a resolver. This allows remote attackers to poison DNS caches via unknown vectors.
Recommendations For versions prior to 8.4.7-P1, update to version 8.4.7-P1 or later to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2930
HPSBUX02289

Produtos afetados

Bind Server
Hp-Ux
Isc Bind